Data Retention and Deletion Non-Compliance
Personal or regulated data kept beyond its lawful basis, or deletion requests not honoured throughout.
- Remediation SLA
- 30 days
- Tier
- 2 · Regulatory
- Domain
- Data
- Escalation
- Security manager review at 14 days
What this finding is
Data is retained past the period justified by its lawful basis or business need, or deletion is incomplete — records removed from a primary database while persisting in backups, analytics warehouses, log aggregation, search indexes, and third-party processors. Also covers the absence of any defined retention schedule.
Why it is Tier 2
Storage limitation is a substantive obligation under GDPR Article 5(1)(e), and data-subject erasure rights under Article 17 carry direct regulatory exposure. Retained data is also breach exposure that produces no business value — the cheapest possible reduction in blast radius is deleting what you should not still hold. Tier 2 reflects that the consequence is regulatory rather than immediate compromise.
Most common misclassification
How to detect it
- 1Compare the documented retention schedule against actual data ages per system; the absence of a schedule is itself the finding.
- 2Trace a test deletion request end to end through every downstream system, which is where incompleteness is found.
- 3Enumerate secondary copies — warehouses, backups, search indexes, caches, logs, and processor systems — and confirm each is in scope for deletion.
- 4Review processor contracts for deletion obligations and confirm they are exercised rather than merely agreed.
How to remediate it
Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.
- 1Publish a retention schedule per data category with the lawful basis and retention period stated.
- 2Automate deletion at the end of the retention period rather than relying on periodic manual purges.
- 3Extend deletion to every downstream copy, and where backup architecture makes selective deletion impractical, document the compensating approach — typically encryption with per-subject key destruction.
- 4Establish a data-subject request process with a tracked service level.
- 5Instruct processors to delete on the same schedule and retain their confirmations.
How to verify the fix
A test data-subject erasure request completes across all identified systems within the statutory period, evidenced per system, and automated retention deletion is observed executing on schedule.
Mappings
Attacker techniques
- T1213Data from Information Repositories
Compliance mappings
- GDPRArt. 5(1)(e) / Art. 17 — storage limitation and erasure
- PCI DSS v4.03.2.1 — retain account data only as required
- ISO/IEC 27001:2022A.5.33 — protection of records